kevmap

Techniques › T1039

T1039 Data from Network Shared Drive

collection — Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
2
Sigma rules tagged attack.t1039
0
KEV CVEs mapped here
<p>Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared directory, network file server, etc.) that are accessible from the current system prior to Exfiltration. Interactive command shells may be in use, and common functionality within cmd may be used to gather information.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1039

Author: Florian Roth (Nextron Systems), oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Nasreddine Bencherchali · 2019-12-30 (modified 2025-10-22) · logsource: product=windows category=process_creation · 855bc8b5-2ae8-402e-a9ed-b889e6df1900
Detects a copy command or a copy utility execution to or from an Admin share or remote
Author: Samir Bousseaden · 2019-04-03 (modified 2025-10-17) · logsource: product=windows service=security · 91c945bc-2ad1-4799-a591-4d00198a1215
Detects known sensitive file extensions accessed on a network share
Techniques: T1039